Compliance software for IT teams
The human side of compliance.
Describe how your team works. Adhera writes it up for the auditor, guides each person through their evidence, and counts each control for every framework it covers.
Days to start. Not quarters.
A private preview for design partners.Production change ticket CHG-0142.png
Meridian Payments · Q3 2026
Question 1 of 3
The ticket says awaiting approval. The change isn't approved yet.
Illustration based on the product
Describe it
Describe it or show it. Adhera writes it for the auditor.
Explain a control the way you'd brief a new engineer, or record yourself doing it once. Adhera names it, asks what an auditor would ask, and drafts your team's tasks. You review every draft before it counts.
Adhera asks
"Is any of this already written down?"
Start here- Risk and control matrix.xlsxReady to read
- Information security policy.pdfReady to read
- System inventory.csvReady to read
Here's what I found
- 3 entities
- 3 frameworks
- 5 systems
- 6 controls
Two documents disagree on one detail.
Quarterly access review: the matrix says quarterly, the policy says annually. You choose which to keep.
Nothing is saved yet. You confirm each detail as you go.
Show how it's done
Do the review once, in one window.
Watch it back
Nothing has left your browser yet.
Working out the tasks from the recording…
Reading your walkthrough
What it read
Export and review the helpdesk access list
- Open Users in the helpdesk admin console0:04
- Export the user list0:15
- Mark leavers for removal0:29
- Send the list to the IT manager to sign off0:44
A draft for you to check.
1 task drafted from your walkthrough. Nothing counts until you save it.
Adhera asks
"What's the name of this control?"
Adhera asks
"Can you walk me through how it works?"
Adhera reads it back
Quarterly access review for the helpdesk system
Proposed referenceCC6.1 – Logical and physical access
An auditor would ask:
The exported list, signed off by the IT manager, is the record.
Sam's walkthrough doesn't say yet, so name who covers the review.
Sam removes the access, then the IT manager signs off the list.
Drafted tasks
- Export the access listSamSuggested
- Review and remove accessSamSuggested
- Sign off the reviewIT managerSuggested
Review, edit or remove anything before saving.
3 tasks drafted. Nothing counts until you save it.
Do it right
Your team gets it right the first time.
Each task says what to do, then asks for exactly the proof it needs. Adhera reads each file as it arrives. It says in plain words what's missing, so it can be fixed before it reaches you.
My work
Hi Sam — welcome back. You have 2 things to work on.
Start hereStep 1 of 2 — What to do
Export the quarterly access list
Export the list of everyone with access to the helpdesk system at Meridian Payments. Include each user and what they can access at the end of Q3 2026.
Step 2 of 2 — Your proof
Reading your instructions, this is what they ask for
Quarterly access list — every user and what they can access.
Attach a sample file.
Attached:
This lists access for Q2 2026, but the task is for Q3 2026.
Reads as a quarterly access list for Q3 2026, covering all users.
Nice work — that one is done. 1 more thing waiting.
Count it everywhere
Do it once, and it counts for every framework.
One access review can serve several companies and several frameworks. In Adhera it's one control with one set of tasks, and every place it applies shows the same evidence.
- Q3 access review · Meridian Group Holdings · SOC 2Open
- Q3 access review · Meridian Group Holdings · ISO 27001Open
- Q3 access review · Meridian Group Holdings · SOX 404Open
- Q3 access review · Meridian Insurance · SOC 2Open
- Q3 access review · Meridian Insurance · ISO 27001Open
- Q3 access review · Meridian Insurance · SOX 404Open
- Q3 access review · Meridian Payments · SOC 2Open
- Q3 access review · Meridian Payments · ISO 27001Open
- Q3 access review · Meridian Payments · SOX 404Open
AC-01Quarterly access review
3 tasks · Q3 2026
9 reviews to run
| SOC 2 | ISO 27001 | SOX 404 |
|---|
Become a design partner
We're shaping Adhera with a small group of IT teams, before general release.
What you get
- Adhera, free for the pilot
- A recurring call with the founders
- A say in what gets built next
What we ask
Honest feedback. Only data you're allowed to share with a service provider.
Pre-release software, no service levels. See Partner terms.
Want to look around first? The demo workspace uses invented data.
FAQ
What is Adhera?
Adhera is compliance software for IT teams. You set up each control once. Your team follows guided tasks to produce the evidence. Each control counts for every framework and company it covers.
Who is it for?
IT leaders who answer to an external auditor for SOC 2, ISO 27001 or SOX, and the engineers who do the work. You don't need an audit background.
Is it available today?
Adhera is in development. Design partners use it now as pre-release software, free for the pilot.
Do auditors log in?
You can add your auditor with the auditor role, limited to the compliance areas you choose. Or send them the response workbook and evidence pack for each audit.